CVE-2026-43499 GhostLock: rtmutex use-after-free since Linux 2.6.39, fixed in 7.1. Nebula Security VEGA team. Local privilege escalation and container escape. $92,337 Google kernelCTF bounty. Part of 2026 Linux kernel vulnerability wave (Januscape, Bad Epoll, DirtyClone, etc.).